
Полная версия:
Min Xie Cyber-Physical Distributed Systems
- + Увеличить шрифт
- - Уменьшить шрифт
Thus, the data‐driven degradation model with unit‐to‐unit variability is integrated into the control system model described by control block diagram, resulting in a real‐time simulation model. In such control models, the interplay among the reduction in the control signal due to component degradation, the transfer functions of the subsystems, and the feedback control loop, provides the mapping between the component degradation states and the system performance loss. This interaction is modeled via control‐block diagrams, which implement the feedback control mechanism and quantify the control signal by comparing the control performance to the setpoint. Therefore, such an integrated model does not require explicit mapping from the component degradation states to the system performance loss and is well‐suited to represent a degraded control system. As such, this simulation model realistically predicts the performance of the control system at different operating times and degradation stages.
1.3.2 Ensuring Cybersecurity of CPSs
Attacks on complex systems, for example, CPSs, are fundamentally different from traditional internal failures (e.g., degradation and design) and external failures (e.g., natural disasters) [296][297][298][299]. Many attack models for complex systems embrace a partial perspective, which only focuses on component vulnerability, and neglects the dependence of system performance on it [300][301][302]. As a result, the insights provided by these models are not adequate for providing general recommendations in realistic applications. To address this limitation, recent studies investigate the influence of component vulnerability (attacks at the component level) on system performance [303][304][305][306].
Pioneering works [307][308][309][310][311][312] develop optimal defense strategies to minimize the attachment vulnerability of parallel systems, assuming that attackers maximize either the damage probability or the expected damage over a time horizon. They also consider general features, that is, imperfect false target techniques and genuine targets [313][314]. These defense strategies reach a trade‐off between increasing the protection of existing components and providing redundancy by allocating additional components [315][316][317][318].
System performance is an essential feature in CPSs that can still operate if some components are unavailable and, therefore, are characterized by multiple performance levels [319][320][321][322][323][324]. System performance degrades with increasing component destruction or unavailability; if the system performance level decreases, the required demand may be partially unsatisfied. Two risk measures can be used for multi‐state complex systems [325][326][327]: 1) the probability that the demand is not satisfied is considered for complex systems that fail if performance cannot meet demand, for example, automatic train protection and block systems [328][329], and power system dynamic security systems [330]; 2) the expected damage proportional to the unsupplied demand is considered for complex systems that can operate even if the demand is partially supplied, for example, mobile ad hoc networks [331], NCSs [332][333], supervisory control and data acquisition (SCADA) systems [334][335], water distribution networks [336], and electric power grids [337][338][339].
Several works consider both the vulnerability and performance of complex systems subject to attacks [340][341][342][343][344][345][346][347][348]. These works generally describe a case as a dynamic contest between an attacker and a defender to develop a component vulnerability model and a multi‐state system performance model. The number of destroyed components quantifies the demand loss and expected damage costs [349][350]. To make the above contest more realistic, attack time uncertainties and the attacker's preference on the attack time should be considered.
In the literature, two different approaches exist for determining the attack time, that is, the strategic selection and the selection based on probability distributions. In the former, the attacker strategically selects whether to attack at some point in time or at a later point in time, based on the outcome of the game, given that the attack occurs at a specific time [351]. Thus, complex attack and defense strategies can be derived from a two‐stage min‐max multi‐period game. Extensive attack or defense in one period limits the attack or defense that can be exerted in the next period, and vice versa. Thus, players strategically choose whether to exert effort now or in the future [352][353][354]. The defender may determine optimal resource allocation strategies for redundancy [355] and protection, that is, individual or overarching protection [356][357][358][359]. On the other hand, the attacker may distribute the constrained resources optimally across sequential attacks [360][361][362][363].
In the second approach, the attacker prefers to conduct the attack at the time of the critical event [364]. Indeed, attacks in Nice, Berlin, Manchester, and London occurred several days before and after Bastille Day, Christmas, a concert, and the Champions League 2017 Final, respectively. In these cases, the defenders have increased the protection level in the immediate aftermath; therefore, it is not worthwhile and cost‐effective for the attacker to deploy another attack in a short period. Because attacks occurred at critical times, they can greatly influence public opinion. As a result, the attacker aims to maximize the system loss by strategically selecting a set of elements to attack based on the two‐stage min‐max game [365]. Because we can predict the distribution of the time at which the critical event occurs, the attack time can be inferred from a data‐driven probability distribution [366]. The two approaches aim to maximize the outcomes of the game given that the attack occurs at a specific time under a similar system structure and variable resources.
The truncated normal distribution is used to describe the uncertainty of the most probable attack time, that is, the time of the critical events, and the accuracy of the defender's estimate of it [367][368][369]. The truncated normal distribution has been adopted to represent uncertainties in many realistic applications, for example, traffic peaks of online video websites [370], the peak season of power supplies [371][372][373], the peak demand of water distribution systems [374], and the rush hour of public transportation [375]. Accounting for the influence of this uncertainty increases the relevance of the insights gained for the optimal resource allocation strategy against attacks.
CPSs are a new class of engineered complex systems that provide tight interactions between cyber and physical components. The corruption of a small subset of their components has the potential to trigger system‐level failures leading to entire system performance disruptions [376][377][378][379]. Previous studies on attack vulnerability and performance of complex systems can be extended to identify resource allocation strategies for cyber components and promote system performance during cyber‐attacks in CPSs [380][381]. Cyber vulnerabilities are exploited by attackers to launch insidious attacks on the integrity, confidentiality, and availability of cyber data by injecting false data into measurement devices, eavesdropping estimation of system states, and deploying denial of service (DoS) attacks on communication networks [382][383][384][385]. More sophisticated attack models specifically target weaknesses to cause maximal damage [386]. In this respect, it is key to capture the uncertainties intrinsic to the behavior of the attacker and the defender.
With respect to applications in smart grids, upgrading traditional grids to smart grids has brought many benefits to the overall management of power and energy systems, including higher reliability, better efficiency, improved integration of RERs, more flexible choice for stakeholders, and lower operation costs [387][388][389]. However, the core technologies, for example, communication techniques and SCADA systems [390][391][392][393], which deliver the advantages of smart grids, also open the grids to vulnerabilities that already exist in the information and communications technology (ICT) world. These vulnerabilities pose threats to smart grids, such as DoS attacks, false data injection, replay attacks, privacy data theft, and sabotage of critical infrastructure [394][395][396]. In addition, the failures in a smart grid caused by cyberattacks can easily cascade to other highly dependent critical infrastructure sectors, such as transportation systems, wastewater systems, health care systems, and banking systems, resulting in extensive physical damage and social and economic disruption [397][398].
While government, the private sector, and academia are recognizing the cyber vulnerability of smart grids, the likelihood and impact of a cyberattack are difficult to quantify. Furthermore, for a smart grid, there may be mandatory standards and operational requirements from grid stakeholders. Current risk management strategies are generally qualitative or heuristic [399]. In these strategies, some assumptions, for example, constant reward with respect to successful anti‐cyberattack [400][401], may be unrealistic for most smart grids.
Chapter 7 presents a probabilistic risk analysis framework to enhance smart grid cyber security. In particular, the dynamic and stochastic characteristics of smart grids, such as uncertain demands, are taken into account to investigate the effect of defending strategies on the real operation cost. The optimal power flow (OPF) model [402] is applied to an 11‐node radial smart grid originating from the Elia grid in Belgium. Compared with the existing studies that focus on the inherent risk [403][404], such as the natural degradation and uncertain RERs for better maintenance actions and power dispatch, Chapter 7 addresses the impact of the external threat (cyberattacks) on the operation cost for effective deployment of cyber defense teams. In previous works, the cost of each attack on a node was assumed to be a constant [405]. Nevertheless, by investigating some practical scenarios, it has been found that the costs are more likely to be determined by some adversarial factors. Therefore, an adversarial cost sequence associated with each node is assumed, and a widely used variation constraint is introduced for each cost sequence. To cope with the objective of sequential decision strategies, the problem is formulated using the reinforcement learning framework [406][407][408]. In particular, the Bayesian prior method [409] is employed for the model parameters, and the problem is formulated as a Bayesian adversarial multi‐node bandit model. In addition, a Bayesian minimax type regret function is constructed, which is subject to the learning context.
2
Fundamentals of CPSs
In this chapter, fundamental Cyber-Physical System (CPS) models, evaluation processes, verification procedures and optimization methods are introduced.
As the CPS lacks an explicit formulation due to the feedback control mechanisms [410][411], the closed‐form solution of the optimal stability, reliability and resilience strategies is unavailable. Therefore, meta‐heuristics algorithms are employed to assist the search of the optimal strategy. For maintenance of CPSs, we use the hybrid Genetic‐Simulated‐Annealing algorithm (HGSAA), which has been applied in many maintenance optimization works [412][413][414]. It combines the Genetic Algorithms (GA) and the Simulated Annealing (SA) to improve the quality of solutions and reduce computation efforts [415]. For the optimal control strategy of CPSs (single objective), A particle swarm optimization (PSO) method based on Monte Carlo Simulation (MCS) is introduced in this book to solve the Proportional–Integral–Derivative (PID) controller optimization problem [416][417]. The method can achieve higher search efficiency values since it combines local search with global search. The technique has been widely employed to find optimal solutions for realistic applications, especially with regard to the optimization of control systems [418][419][420]. A solution including the PID control strategy is encoded as a finite‐length string called “a particle” in PSO. The fitness value of each particle is determined by a fitness function. However, the optimization of PID usually involves simultaneous optimizing two objectives, i.e., control performance and control effort, which are generally non‐commensurable and conflicting with each other [421][422]. Better control performance means more control efforts and vice versa. Therefore, the multi‐objective PSO algorithm is applied to achieve a best trade‐off between the two objectives [423][424][425].
2.1 Models for Exploring CPSs
2.1.1 Control‐Block‐Diagram for CPSs
Consider the CPS with degraded components shown in Figure 2.1, which is a typical case of CPSs consisting of a forward channel and a feedback channel.

Figure 2.1 The control block diagram of CPSs with degraded components.
2.1.1.1 Control Signal in CPSs
At the total run time To, for an operational task with total K sampling periods, the time‐varying model of the forward channel in the kth period (k ∈ {1, …, K}) is first derived.
As the sensor measures the system output during every sampling period TP, the control signal uk remains the same during the interval [(k − 1)TP, TP], which is the inherent discrete‐time property. Thus, the control signal uk can be represented by the following sum of input steps:

(2.1)
where

Arriving at the relationship between control signal uk and output yk is not a trivial task. In the time domain, it cannot be represented by the simple multiplication of time‐varying model of the actuators, their respective degradations, and the process, but their convolution. Inspired by a similar problem solved by control theory, by applying the Laplace transform to respective time‐varying models of the actuators, degradations, and the process, their respective complex domain models can be obtained. Once this is done, the overall relationship can be described through simple multiplication of the complex domain models.
Firstly, applying the Laplace transform to uk, its complex domain representation is:

(2.2)
where


2.1.1.2 Degraded Actuator and Sensor
Since the system has N identical actuators, for any n ∈ {1, 2, …, N}, the degradation of the nth actuator can be modeled by a Wiener‐process subject to unit‐to‐unit variability [426][427]:

(2.3)
where dan(To) denotes the loss in the effectiveness of the nth actuator at total run time To. dan(0) is a known initial degradation state. Without loss of generality, it is assumed that dan(0) = 0 in this book. For any To > 0, σB(To) ∼ N(0, σ2To) describes the stochastic dynamics of the degradation process.
It is found that (2.3) is able to describe the time‐varying variability arising from the dynamic features of B(To). Nevertheless, since each actuator operates under different working conditions, different actuators follow different degradation paths at different rates. Compared with previous works where the degradation processes are identical, it is more realistic to consider the unit‐to‐unit variability in the degradation process. Thus, θ is regarded as a random parameter denoting the unit‐to‐unit variability with

Assumption 2.1: For any kTP ≪ To, dan(To + kTP) equals to dan(To). Thus, dan(To + kTP) is a constant value during an operational task starting at total run time To. The values of θ and B(To) are independent of each other.
Since the operational time of one control process is much smaller than the total run time of entire CPSs in real applications, it is general to consider that the change in the degradation of one component is negligible in such a short time [428][429]. Therefore, above assumption is reasonable and not restrictive.
Since the degradation of each actuator is constant during an operational time interval [To, …,To + KTP], the Laplace transform cannot be applied to a constant value. Even so, the relationship between control signal and system output can still be represented by simply multiplying the time‐varying models of the actuators and the process and the degradation constant as:

(2.4)
where

In industrial applications, the perfect sensor measurement of system output state is often impossible. It is the common case for the controller that the received sensor measurements are not only subject to measurement error but also to sensor gain degradation due to the noise and severe working conditions [430][431]. Therefore, the received measurement in the kth period is a superposition of the measurement error wk and sensor gain degradation ds(To + kTP) with

(2.5)
where the ds(To) accounts for the stochastic sensor gain degradation at total time To, ds(0) is the initial state with ds(0) = 0, and λ is the drift coefficient with λ < 0. Compared with the aforementioned models in which ds(To) is restricted to be a constant or follow a uniform or Bernoulli distribution, (2.5) is more suitable to describe the time‐varying properties of the sensor gain degradation.
Assumption 2.2: For any k and kTP ≪ To, ds(To + kTP) equals to ds(To) during an operational task starting at time To. ds(To), and wk and da(To) are independent of each other.
Thus, the measurements received by the controller can be described as

(2.6)
2.1.1.3 Time‐Varying Model of CPSs
Therefore, substituting (2.2) into (2.4), and using the linearity property of Laplace transform and applying the inverse Laplace transform to (2.4), the output yk can be obtained as


(2.7)

where


After completing the forward and inverse Laplace transform, the time‐varying model of the forward channel is built. Consider now the time‐varying model of the feedback channel.
Right after the controller receives the measurement of the system output yk in (2.6), it will compute the control signal for each actuator at the (k + 1)th period, separately. For simplification, it is assumed that all actuators share the control signal evenly.
Thus, the control signal for actuator n based on the following PID strategy is determined as:

(2.8)
where ek + 1 = rk + 1 − yk.
From (2.8), it can be concluded that the control signal computed is determined actually by historical errors. Properly designing the parameters of the control strategy can definitely help the system eliminate the influence caused by degraded components and make the system output converge to the expected target with required qualities.
Therefore, the stochastic model of CPSs is closed through the forward channel model expressed by (2.1) and (2.7), and the feedback channel model expressed by (2.6) and (2.8). The performance analysis and reliability improvement can be conducted based on the explicit system structure by optimally choosing the parameters of the system controller.
2.1.2 Implementation in TrueTime Simulator
2.1.2.1 Introduction of TrueTime Simulator
The architecture for the Automatic Generation Control (AGC) of Distributed Energy Resources (DERs) via Ethernet and hybrid network, is illustrated by the Figure 2.2. To implement the microgrid with two different communication network architectures in the Matlab/Simulink environment, the TrueTime simulator is deployed for simulating different types of communication protocols [432].


Figure 2.2 Simulink realization of the microgrid. (a) Ethernet, (b) Hybrid network.
TrueTime is a Matlab/Simulink‐based simulator for real‐time CPSs, which facilitates co‐simulation of controller task execution in real‐time kernels, network transmissions, and continuous plant dynamics. It can simulate most realistic communication networks, e.g., Ethernet, CAN, TDMA, FDMA, Round Robin, Switched Ethernet, FlexRay, PROFINET, 802.11b WLAN and 802.13.4 ZigBee. Multiple activity levels of the interfering traffic are simulated via the Interference node, which sends random interfering packets over the network. Packet dropout is described by Bernoulli‐distributed variables [433]. More details of TrueTime simulator and its realization in CPSs are given in this Section.
Above procedure is detailed in the “TrueTime 2.0‐Reference Manual”, which provides representative examples of CPSs [434]. Figure 2.2 (a) and Figure 2.2 (b) present the Matlab/Simulink implementations of the microgrid with Ethernet and of the microgrid with Hybrid network, respectively. The network blocks from the TrueTime simulator are directly linked with physical components, i.e., the PID controller, Phasor Measurement Units (PMU), DERs, to enable data exchanges.
The data exchange among the control center, DERs, interference node and PMU are wired in the Ethernet architecture. In the hybrid architecture, the data exchange between the routers and the Remote Terminal Unit (RTU), such as Battery Energy Storage Systems (BESS), Flywheel Energy Storage Systems (FESS), Diesel Engine Generator (DEG) and PMU, is wireless and provided by the 802.11b/g. The data exchange among routers is wired and provide by the Ethernet. Low product prices make 802.11b/g more convenient and cost‐effective compared to the Ethernet. As such, 802.11b/g has become an efficient approach to provide flexible data communication between routers and RTU, and is employed for monitoring and controlling DERs, offshore wind farms and smart home energy management systems [435].
